Known Vulnerabilities for Taocms by Taogogo
Listed below are 10 of the newest known vulnerabilities associated with "Taocms" by "Taogogo".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-34654 json | taocms <=3.0.2 is vulnerable to Cross Site Scripting (XSS). | 6.1 - MEDIUM | 2023-07-05 | 2023-07-10 |
| CVE-2023-1947 json | A vulnerability was found in taoCMS 3.0.2. It has been classified as critical. Affected is an unknown function of the file /a... | 9.8 - CRITICAL | 2023-04-07 | 2023-11-07 |
| CVE-2022-48006 json | An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. Th... | 9.8 - CRITICAL | 2023-01-30 | 2023-02-07 |
| CVE-2022-46998 json | An issue in the website background of taocms v3.0.2 allows attackers to execute a Server-Side Request Forgery (SSRF). | 9.8 - CRITICAL | 2023-01-26 | 2023-02-01 |
| CVE-2022-36262 json | An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying c... | 9.8 - CRITICAL | 2022-08-15 | 2023-11-07 |
| CVE-2022-36261 json | An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server when r... | 9.1 - CRITICAL | 2022-08-23 | 2023-11-07 |
| CVE-2022-25578 json | taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file. | 9.8 - CRITICAL | 2022-03-18 | 2022-03-28 |
| CVE-2022-25505 json | Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.php. | 9.8 - CRITICAL | 2022-03-21 | 2022-03-29 |
| CVE-2022-23880 json | An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute ar... | 9.8 - CRITICAL | 2022-03-23 | 2022-03-28 |
| CVE-2022-23380 json | There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit. | 8.8 - HIGH | 2022-03-01 | 2022-03-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Taogogo | Taocms | 2014-05-24 |